Local Privilege Escalation in AccountsService for Ubuntu Users
CVE-2026-61897

7.8HIGH

Key Information:

Vendor

Canonical

Vendor
CVE Published:
20 August 2026

What is CVE-2026-61897?

A vulnerability in AccountsService allows for local privilege escalation due to insufficient privilege dropping before executing language helper scripts. This issue arises from the effective user ID and group ID changing to the target user, while the real user ID remains set to 0 (root). As a consequence, a shell launched by a helper script can inherit a real user ID of 0, enabling the possibility to regain root privileges. Users must update to the patched version to mitigate this security risk.

Affected Version(s)

accountsservice Ubuntu 14.04 LTS 22.07.5-2ubuntu1 < 22.07.5-2ubuntu1.6

accountsservice Ubuntu 14.04 LTS 23.13.9-2ubuntu6 < 23.13.9-2ubuntu6.1

accountsservice Ubuntu 14.04 LTS 23.13.9-8ubuntu5 < 23.13.9-8ubuntu5.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Deutsche Telekom Security GmbH Red Team
.